Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Your company uses Microsoft Defender for Endpoint (MDE) and wants to integrate threat intelligence from an external source to improve detection. The security team needs to ingest custom indicators of compromise (IOCs) into MDE. Which feature should they use?

⚠ Common exam trap

A common mix-up: candidates confuse 'Advanced Hunting' (a query tool) with a feature for importing threat data, or they mistakenly think 'Threat Analytics' allows custom feed integration, when in fact it only displays Microsoft's pre-built analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Custom indicators (IOCs)

The Custom Indicators (IOCs) feature in Microsoft Defender for Endpoint allows security teams to manually ingest and manage threat intelligence from external sources, such as IP addresses, URLs, domains, or file hashes. These indicators are then used by MDE to create or block alerts, enabling tailored detection beyond built-in threat intelligence feeds.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Advanced Hunting

    Why it's wrong here

    Advanced Hunting is a Kusto Query Language (KQL)-based threat hunting tool that queries Microsoft Defender for Endpoint's raw event tables for up to 30 days. It does not provide a mechanism to import or ingest external Indicators of Compromise (IOCs); it only consumes existing data for retrospective analysis and custom detections, not for feeding new indicators into the product. Therefore, it cannot be used to turn on a connector that imports IOCs from an external source into the environment's intelligence.

  • ✗

    Threat Analytics

    Why it's wrong here

    Threat Analytics is a curated set of threat intelligence reports from Microsoft security researchers, delivered as in-product articles that detail active campaigns, tactics, techniques, and relevant mitigation actions. These reports are read-only and generated by Microsoft; they cannot be configured to import a customer's external Indicators of Compromise (IOCs) into Defender for Endpoint. As such, it serves as an advisory tool rather than an ingestion endpoint for custom threat intelligence.

  • ✗

    Automated investigation and response

    Why it's wrong here

    Automated Investigation and Response (AIR) is the engine in Microsoft Defender for Endpoint that automatically investigates alerts, identifies suspicious entities, and applies remediation actions like quarantining files or blocking URLs. Its execution relies on indicators and detections already present in the product; it offers no inbound API or UI to import external Indicators of Compromise (IOCs) for ingestion. Thus, enabling AIR would not enable a connector to pull IOC data into the environment.

  • ✓

    Custom indicators (IOCs)

    Why this is correct

    Custom Indicators (IOCs) is the Microsoft Defender for Endpoint feature that allows tenants to import their own threat intelligence, including file hashes, IP addresses, URLs, domains, and certificates, from external sources. This ingestion can be performed through the Microsoft 365 Defender portal or programmatically via APIs, and the imported indicators are then evaluated during detection and enforcement. Enabling a connector to import IOCs from an external source specifically leverages this feature, as it is the sole mechanism among these options that accepts and manages external indicator data.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.